Docker - SecurityWhich of the following is a recommended practice by CIS Docker Benchmark for container images?AUse the latest tag for all imagesBAlways run containers as root userCDisable image scanning for faster deploymentDUse minimal base images to reduce attack surfaceCheck Answer
Step-by-Step SolutionSolution:Step 1: Review CIS recommendation on imagesCIS advises using minimal base images to reduce vulnerabilities and attack surface.Step 2: Evaluate other optionsRunning as root, disabling scanning, and using latest tag are discouraged for security reasons.Final Answer:Use minimal base images to reduce attack surface -> Option DQuick Check:Image security = Minimal base images [OK]Quick Trick: Minimal images reduce vulnerabilities and improve security [OK]Common Mistakes:Running containers as root userIgnoring image scanningUsing 'latest' tag blindly
Master "Security" in Docker9 interactive learning modes - each teaches the same concept differentlyLearnWhyDeepVisualTryChallengeProjectRecallTime
More Docker Quizzes Docker Swarm - Swarm mode initialization - Quiz 13medium Docker in CI/CD - Pushing images from CI - Quiz 5medium Image Optimization - Analyzing image layers with dive - Quiz 2easy Image Optimization - Analyzing image layers with dive - Quiz 15hard Image Optimization - Scratch base image for minimal containers - Quiz 4medium Logging and Monitoring - Docker events monitoring - Quiz 8hard Logging and Monitoring - Grafana dashboards for containers - Quiz 15hard Production Patterns - Backup and restore strategies - Quiz 6medium Production Patterns - Canary deployment pattern - Quiz 5medium Resource Management - Why resource limits matter - Quiz 3easy